package middleware import ( "net/http" "net/http/httptest" "testing" "github.com/gin-gonic/gin" "github.com/stretchr/testify/assert" ) func TestXSSProtection_DefaultConfig(t *testing.T) { cfg := DefaultXSSProtectionConfig() assert.NotNil(t, cfg.HTMLPolicy) assert.True(t, cfg.SanitizeJSONResponse) assert.True(t, cfg.SanitizeInputFields) } func TestXSSProtection_SanitizeHTML(t *testing.T) { cfg := DefaultXSSProtectionConfig() result := SanitizeHTML("safe", cfg.HTMLPolicy) assert.NotContains(t, result, "", nil) r.ServeHTTP(w, req) assert.Equal(t, 200, w.Code) } func TestXSSProtection_SanitizeQuery(t *testing.T) { gin.SetMode(gin.TestMode) cfg := DefaultXSSProtectionConfig() r := gin.New() r.Use(XSSProtectionMiddleware(cfg)) r.GET("/test", func(c *gin.Context) { name := c.Query("name") c.JSON(200, gin.H{"name": name}) }) w := httptest.NewRecorder() req := httptest.NewRequest(http.MethodGet, "/test?name=", nil) r.ServeHTTP(w, req) assert.Equal(t, 200, w.Code) } func TestUGCPolicy(t *testing.T) { p := UGCPolicy() assert.NotNil(t, p) } func TestShouldSanitizeField(t *testing.T) { cfg := DefaultXSSProtectionConfig() assert.True(t, shouldSanitizeField("name", cfg)) assert.True(t, shouldSanitizeField("content", cfg)) assert.False(t, shouldSanitizeField("id", cfg)) }